JLSEC-2026-627

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-627.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-627.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-627
Upstream
  • EUVD-2026-23215
  • GHSA-m34r-4v3r-pp9v
Published
2026-06-25T17:41:14Z
Modified
2026-07-25T18:23:58Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
In rsync 3.0.1 through 3.4.1, `receive_xattr` relies on an untrusted length value during a qsort...
Details

In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call, leading to a receiver use-after-free. The victim must run rsync with -X (aka --xattrs). On Linux, many (but not all) common configurations are vulnerable. Non-Linux platforms are more widely vulnerable.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "database_specific": {
                "status": "Modified"
            },
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-41035",
            "id": "CVE-2026-41035",
            "imported": "2026-07-17T22:14:48.043Z",
            "modified": "2026-07-15T02:21:12.250Z",
            "published": "2026-04-16T07:16:31.003Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-41035"
        },
        {
            "html_url": "https://github.com/advisories/GHSA-m34r-4v3r-pp9v",
            "id": "GHSA-m34r-4v3r-pp9v",
            "imported": "2026-07-17T22:14:48.194Z",
            "modified": "2026-07-10T12:31:53Z",
            "published": "2026-04-16T09:31:44Z",
            "url": "https://api.github.com/advisories/GHSA-m34r-4v3r-pp9v"
        },
        {
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23215",
            "id": "EUVD-2026-23215",
            "imported": "2026-07-17T22:14:56.902Z",
            "modified": "2026-07-10T12:05:54Z",
            "published": "2026-04-16T06:53:05Z",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-23215"
        }
    ]
}
References

Affected packages

Julia / rsync_jll

Package

Name
rsync_jll
Purl
pkg:julia/rsync_jll?uuid=191d6b87-264a-55f5-a0e2-c8fbce9a1ce0

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.4.4+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-627.json"